forensic-technique
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted forensic evidence from various sources including disk images, memory dumps, and network captures, which may contain adversarial instructions.
- Ingestion points: Evidence files processed via
scripts/forensic_triage.pyand referenced forensic artifacts (EVTX, PCAP, MFT, registry hives, memory regions) described in thereferences/directory. - Boundary markers: The instructions lack explicit boundary markers or delimiters to differentiate between the agent's instructions and the untrusted data content being analyzed.
- Capability inventory: The skill directs the agent to utilize a wide array of forensic tools such as
volatility3,yara,capa,chainsaw,zeek, andtcpdump, which involves significant file system and diagnostic capabilities. - Sanitization: No specific sanitization or escaping mechanisms are mandated for processing content from external artifacts before they are incorporated into the agent's reasoning context.
Audit Metadata